CVE-2011-4924
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3, 3.1.1 through 3.4.1. allows remote attackers to inject arbitrary web script or HTML via vectors related to the way error messages perform sanitization. NOTE: this issue exists because of an incomplete fix for CVE-2010-1104
Vulnerabilidad de tipo cross-site scripting (XSS) en Zope versiones 2.8.x anteriores a 2.8.12, versiones 2.9.x anteriores a 2.9.12, versiones 2.10.x anteriores a 2.10.11, versiones 2.11.x anteriores a 2.11.6 y versiones 2.12.x versiones anteriores a 2.12.3 , versiones 3.1.1 hasta 3.4.1, permite a atacantes remotos inyectar script web o HTML arbitrario por medio de vectores relacionados con la forma en que los mensajes de error realizan el saneamiento. NOTA: este problema se presenta debido a una soluciĆ³n incompleta para CVE-2010-1104
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-12-23 CVE Reserved
- 2019-11-25 CVE Published
- 2024-08-07 CVE Updated
- 2024-11-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2012/01/19/16 | Mailing List | |
http://www.openwall.com/lists/oss-security/2012/01/19/17 | Mailing List | |
http://www.openwall.com/lists/oss-security/2012/01/19/18 | Mailing List | |
http://www.openwall.com/lists/oss-security/2012/01/19/19 | Mailing List | |
https://access.redhat.com/security/cve/cve-2011-4924 | Third Party Advisory | |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-4924 | Issue Tracking | |
https://security-tracker.debian.org/tracker/CVE-2011-4924 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zope Search vendor "Zope" | Zope Search vendor "Zope" for product "Zope" | >= 2.8.0 < 2.8.12 Search vendor "Zope" for product "Zope" and version " >= 2.8.0 < 2.8.12" | - |
Affected
| ||||||
Zope Search vendor "Zope" | Zope Search vendor "Zope" for product "Zope" | >= 2.9.0 < 2.9.12 Search vendor "Zope" for product "Zope" and version " >= 2.9.0 < 2.9.12" | - |
Affected
| ||||||
Zope Search vendor "Zope" | Zope Search vendor "Zope" for product "Zope" | >= 2.10.0 < 2.10.11 Search vendor "Zope" for product "Zope" and version " >= 2.10.0 < 2.10.11" | - |
Affected
| ||||||
Zope Search vendor "Zope" | Zope Search vendor "Zope" for product "Zope" | >= 2.11.0 < 2.11.6 Search vendor "Zope" for product "Zope" and version " >= 2.11.0 < 2.11.6" | - |
Affected
| ||||||
Zope Search vendor "Zope" | Zope Search vendor "Zope" for product "Zope" | >= 2.12.0 < 2.12.3 Search vendor "Zope" for product "Zope" and version " >= 2.12.0 < 2.12.3" | - |
Affected
| ||||||
Zope Search vendor "Zope" | Zope Search vendor "Zope" for product "Zope" | >= 3.1.1 <= 3.4.1 Search vendor "Zope" for product "Zope" and version " >= 3.1.1 <= 3.4.1" | - |
Affected
|